Networking Forums

Networking Forums > Computer Networking > Windows Networking > Public IPs for servers in DMZ or just good old NAT

Reply
Thread Tools Display Modes

Public IPs for servers in DMZ or just good old NAT

 
 
Thomas Moeller Nexoe
Guest
Posts: n/a

 
      01-07-2010, 06:33 AM

Hi.

We are about to make some changes to our network setup and I have been
put in charge of compiling some documentation on how to best setup our
new network environment.

We will be using a Cisco firewall box and a 3-leg perimeter network
setup with ISA server. So far so good.

I have been administering a similar setup in my previous job where we
used to go for public ip addresses for the public accessible servers in
the ISA DMZ - my opinion is that the pubic ip address scheme gives
easier administration in both the Cisco and in the ISA server in terms
of rules and troubleshooting, but I can't seem to convince my boss about
this. He wants to go for a single public ip address and then use NAT for
the servers. I.E. Translate requests based on ports and forward to the
appropriate servers on the network.

I have heard that the NAT solution provides a slightly more secure setup
because the 'outside' cannot see or know the actual servers ip adress on
the network, but are the advantage of using the NAT solution big enough
versus the easier administration with the public ip address scheme?

I mean. We have a Cisco hardware box and an ISA server 2006 between our
DMZ and the Internet.

Thanks in advance for any input!

--
Best regards,

Thomas Moeller Nexoe
--------------------------------------
Website: http://www.winfrastructure.dk
Blog: http://www.winfrastructure.net
 
Reply With Quote
 
 
 
 
Thomas Moeller Nexoe
Guest
Posts: n/a

 
      01-08-2010, 07:20 AM
On 07-01-2010 08:33, Thomas Moeller Nexoe wrote:
> Hi.
>
> We are about to make some changes to our network setup and I have been
> put in charge of compiling some documentation on how to best setup our
> new network environment.
>
> We will be using a Cisco firewall box and a 3-leg perimeter network
> setup with ISA server. So far so good.
>
> I have been administering a similar setup in my previous job where we
> used to go for public ip addresses for the public accessible servers in
> the ISA DMZ - my opinion is that the pubic ip address scheme gives
> easier administration in both the Cisco and in the ISA server in terms
> of rules and troubleshooting, but I can't seem to convince my boss about
> this. He wants to go for a single public ip address and then use NAT for
> the servers. I.E. Translate requests based on ports and forward to the
> appropriate servers on the network.
>
> I have heard that the NAT solution provides a slightly more secure setup
> because the 'outside' cannot see or know the actual servers ip adress on
> the network, but are the advantage of using the NAT solution big enough
> versus the easier administration with the public ip address scheme?
>
> I mean. We have a Cisco hardware box and an ISA server 2006 between our
> DMZ and the Internet.
>
> Thanks in advance for any input!
>

Any thoughts at all?

--
Best regards,

Thomas Moeller Nexoe
--------------------------------------
Website: http://www.winfrastructure.dk
Blog: http://www.winfrastructure.net
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
public ip allocation to servers behind isp connection hardware Scott Windows Networking 2 03-31-2008 11:46 AM
No ping IP Public from outside but RDC works with the same public Gio21 Windows Networking 3 12-12-2007 05:00 PM
List of free public news servers cyber Wireless Internet 0 11-30-2007 03:44 PM
One public IP but multiple servers (with different domains) sven.clement@gmail.com Linux Networking 6 07-17-2006 01:09 AM
Public wireless and SMTP servers Adam Smith Wireless Internet 8 09-23-2004 04:44 PM



1 2 3 4 5 6 7 8 9 10 11